{"schema_version":"1.7.5","id":"SUSE-SU-2026:2493-1","published":"2026-06-22T15:34:20Z","modified":"2026-06-24T09:00:13.323582618Z","related":["CVE-2023-39325","CVE-2023-45288","CVE-2025-22869","CVE-2025-22870","CVE-2025-22872","CVE-2025-47911","CVE-2025-47913","CVE-2025-47914","CVE-2025-58181","CVE-2025-58190","CVE-2026-29181","CVE-2026-33186"],"upstream":["CVE-2023-39325","CVE-2023-45288","CVE-2025-22869","CVE-2025-22870","CVE-2025-22872","CVE-2025-47911","CVE-2025-47913","CVE-2025-47914","CVE-2025-58181","CVE-2025-58190","CVE-2026-29181","CVE-2026-33186"],"summary":"Security update for containerized-data-importer","details":"This update for containerized-data-importer fixes the following issues:\n\n- Security: re-vendor Go dependencies to address CVEs tracked against\n  containerized-data-importer (backport of upstream PR #4110, post-v1.65.0).\n  Fixed by this update:\n  * google.golang.org/grpc 1.65.0 -> 1.79.3:\n    bsc#1260295 (CVE-2026-33186)\n  * golang.org/x/net 0.33.0 -> 0.48.0:\n    bsc#1238699 (CVE-2025-22870), bsc#1241838 (CVE-2025-22872),\n    bsc#1251495 (CVE-2025-47911), bsc#1251689 (CVE-2025-58190)\n  * golang.org/x/crypto 0.31.0 -> 0.46.0:\n    CVE-2025-22869, CVE-2025-47913, CVE-2025-47914, CVE-2025-58181\n    (no separate CDI bug filed)\n  * go.opentelemetry.io/otel 1.28.0 -> 1.41.0:\n    CVE-2026-29181 (otel is pulled in transitively at 1.39.0 by the grpc\n    bump; pinned to 1.41.0 so the update does not introduce it)\n- Record CVEs already fixed by the x/net release vendored in 1.64.0\n  (x/net 0.33.0), not previously noted in the changelog:\n  bsc#1236523 (CVE-2023-45288), bsc#1230323 (CVE-2023-39325)\n","affected":[{"package":{"name":"containerized-data-importer","ecosystem":"SUSE:Linux Enterprise Module for Containers 15 SP7","purl":"pkg:rpm/suse/containerized-data-importer&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.64.0-150700.9.11.1"}]}],"ecosystem_specific":{"binaries":[{"containerized-data-importer-manifests":"1.64.0-150700.9.11.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2493-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20262493-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1230323"},{"type":"REPORT","url":"https://bugzilla.suse.com/1236523"},{"type":"REPORT","url":"https://bugzilla.suse.com/1238699"},{"type":"REPORT","url":"https://bugzilla.suse.com/1241838"},{"type":"REPORT","url":"https://bugzilla.suse.com/1251495"},{"type":"REPORT","url":"https://bugzilla.suse.com/1251689"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260295"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-39325"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-45288"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-22869"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-22870"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-22872"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-47911"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-47913"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-47914"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-58181"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-58190"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-29181"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33186"}]}