{"schema_version":"1.7.5","id":"SUSE-SU-2026:2609-1","published":"2026-06-24T08:46:20Z","modified":"2026-06-25T06:15:05.318034339Z","related":["CVE-2026-24137","CVE-2026-33186","CVE-2026-33814","CVE-2026-34986","CVE-2026-39821","CVE-2026-39827","CVE-2026-39828","CVE-2026-39829","CVE-2026-39830","CVE-2026-39831","CVE-2026-39832","CVE-2026-39833","CVE-2026-39834","CVE-2026-39835","CVE-2026-42508","CVE-2026-46595","CVE-2026-46597","CVE-2026-46598","CVE-2026-48785"],"upstream":["CVE-2026-24137","CVE-2026-33186","CVE-2026-33814","CVE-2026-34986","CVE-2026-39821","CVE-2026-39827","CVE-2026-39828","CVE-2026-39829","CVE-2026-39830","CVE-2026-39831","CVE-2026-39832","CVE-2026-39833","CVE-2026-39834","CVE-2026-39835","CVE-2026-42508","CVE-2026-46595","CVE-2026-46597","CVE-2026-46598","CVE-2026-48785"],"summary":"Security update for apptainer","details":"This update for apptainer fixes the following issues\n\n- CVE-2026-24137: github.com/sigstore/sigstore/pkg/tuf: legacy TUF client allows for arbitrary file writes with target\n  cache path traversal (bsc#1264177).\n- CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2: path pseudo-\n  header (bsc#1260311).\n- CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE\n  (bsc#1265844).\n- CVE-2026-34986: github.com/go-jose/go-jose/v4,github.com/go-jose/go-jose/v3: crafted JWE input with a missing\n  encrypted key can lead to a denial of service (bsc#1262956).\n- CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation\n  bypass and privilege escalation (bsc#1266656).\n- CVE-2026-39827: memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh\n  (bsc#1266202).\n- CVE-2026-39828: bypass of certificate restrictions in golang.org/x/crypto/ssh (bsc#1266202).\n- CVE-2026-39829: pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh (bsc#1266202).\n- CVE-2026-39830: client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh\n  (bsc#1266202).\n- CVE-2026-39831: bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh\n  (bsc#1266202).\n- CVE-2026-39832: agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent\n  (bsc#1266202).\n- CVE-2026-39833: key constraints not enforced in golang.org/x/crypto/ssh/agent (bsc#1266202).\n- CVE-2026-39834: infinite loop on large channel writes in golang.org/x/crypto/ssh (bsc#1266202).\n- CVE-2026-39835: server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh (bsc#1266202).\n- CVE-2026-42508: auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts\n  (bsc#1266202).\n- CVE-2026-46595: VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh\n  (bsc#1266202).\n- CVE-2026-46597: byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh (bsc#1266202).\n- CVE-2026-46598: pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent (bsc#1266202).  \n- CVE-2026-48785: incorrect path matching for limit container paths directive (bsc#1267982).\n\nChanges for apptainer:\n\n- Update apptainer to version v1.5.1\n \n * Work around segmentation fault sometimes seen while `mksquashfs`\n under proot is creating a SIF file.\n * Update bundled PRoot to version 5.4.0-rootless.3 in order to\n fix a problem where SIF files could be corrupted when\n `mksquashfs` died with a signal. The proot command was not\n passing back an error exit code.\n * Updated bundled `squashfuse_ll` to version 0.6.2 in order to\n fix a crash sometimes seen with apptainer in unprivileged\n docker.\n * Update bundled fuse2fs to version 1.47.4 instead of patching\n the bugs in 1.47.3.\n * Fix a crash that happened when `/etc/resolv.conf` was a\n symlink while building from a definition file using the\n localimage bootstrap.\n * Support hosts that have an /etc/resolv.conf symlink pointing\n to `../run` in addition to `/run`.\n * Change the download-dependencies script to skip downloading\n the PRoot source code on architectures that it is known to\n not support (that is: ppc*, s390*, and riscv*).\n In those situations Apptainer will skip trying to compile\n and run proot. As a result original owners and groups of\n files will not be preserved in SIF images built by\n unprivileged users, as was the case for all architectures\n prior to 1.5.0.\n * Fix panic encountered during progress bar update while\n pulling image.\n * Fix fakeroot overwriting root's username in `/etc/passwd`\n with the host user's name, a regression introduced in v1.5.0.\n * Add nonested flag for --mount specifications to prevent\n individual bind mounts from being passed to nested containers\n via `APPTAINER_BIND`.\n","affected":[{"package":{"name":"apptainer","ecosystem":"SUSE:Linux Enterprise Module for HPC 15 SP7","purl":"pkg:rpm/suse/apptainer&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.5.1-150600.4.24.1"}]}],"ecosystem_specific":{"binaries":[{"apptainer":"1.5.1-150600.4.24.1","apptainer-sle15_7":"1.5.1-150600.4.24.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2609-1.json"}},{"package":{"name":"apptainer","ecosystem":"SUSE:Linux Enterprise Server 15 SP6-LTSS","purl":"pkg:rpm/suse/apptainer&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.5.1-150600.4.24.1"}]}],"ecosystem_specific":{"binaries":[{"apptainer":"1.5.1-150600.4.24.1","apptainer-sle15_6":"1.5.1-150600.4.24.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2609-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20262609-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260311"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262956"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264177"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265844"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266202"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266656"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267982"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-24137"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33186"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33814"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34986"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39821"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39827"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39828"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39829"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39830"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39831"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39832"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39833"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39834"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39835"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42508"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46595"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46597"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46598"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48785"}]}