{"schema_version":"1.7.5","id":"SUSE-SU-2026:2976-1","published":"2026-07-14T11:39:57Z","modified":"2026-07-15T10:00:08.925880715Z","related":["CVE-2026-25541","CVE-2026-41676","CVE-2026-41677","CVE-2026-41678","CVE-2026-41681","CVE-2026-41898","CVE-2026-42327","CVE-2026-44662","CVE-2026-45784"],"upstream":["CVE-2026-25541","CVE-2026-41676","CVE-2026-41677","CVE-2026-41678","CVE-2026-41681","CVE-2026-41898","CVE-2026-42327","CVE-2026-44662","CVE-2026-45784"],"summary":"Security update for afterburn","details":"This update for afterburn fixes the following issues\n\nUpdate to version 5.10.0.git73.b97f772.\n\nSecurity issues fixed:\n\n- CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1\n  (bsc#1270175).\n- CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length\n  (bsc#1270555).\n- CVE-2026-41678: openssl: incorrect bounds assertion in `aes::unwrap_key()` can lead to OOB write (bsc#1270651).\n- CVE-2026-41681: openssl: `MdCtxRef::digest_final()` writes past caller buffer with no length check (bsc#1270787).\n- CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent\n  memory to network peers (bsc#1270817).\n- CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders` when processing certificates with non-UTF-8\n  OCSP URLs (bsc#1270483).\n- CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key-wrap-with-padding (bsc#1270886).\n- CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers\n  (bsc#1270949).\n- CVE-2026-25541: bytes: integer overflow in `BytesMut:reserve` can lead to undefined behavior and crashes\n  (bsc#1271348).\n\nOther updates and bugfixes:\n\n- Version 5.10.0.git73.b97f772:\n  * build(deps): bump anyhow from 1.0.99 to 1.0.103\n    https://github.com/coreos/afterburn/pull/1284\n  * build(deps): bump libflate from 2.1.0 to 2.2.2\n    https://github.com/coreos/afterburn/pull/1283\n  * build(deps): bump openssl from 0.10.79 to 0.10.80\n    https://github.com/coreos/afterburn/pull/1277\n- Version 5.10.0.git70.9cc2a7b:\n  * build(deps): bump openssl from 0.10.78 to 0.10.79\n  * providers/hetzner: Add the HETZNER_PUBLIC_IPV6 attribute\n  * providers/hetzner: Add support for network configuration\n  * build(deps): bump rustls-webpki from 0.103.10 to 0.103.13\n  * build(deps): bump openssl from 0.10.73 to 0.10.78\n  * docs: Add AGENTS.md and CLAUDE.md for AI coding assistants\n  * build(deps): bump rand from 0.9.2 to 0.9.4\n  * opencode: add skills for provider scaffolding and release automation\n  * ibmcloud-classic: Add missing network_id to fixture\n  * kubevirt: Support static gateway and DNS with DHCP\n  * build(deps): bump rustls-webpki from 0.103.6 to 0.103.10\n  * fix(proxmoxve): Define DNS entries for every interface\n  * Makefile: download `90-afterburn-authorized-keys-file.conf` for rpm building\n  * Sync repo templates ⚙\n  * build(deps): bump bytes from 1.10.1 to 1.11.1\n  * util/dhcp: Fix clippy lints\n  * build(deps): bump actions/checkout from 4 to 6\n  * build(deps): bump actions/upload-artifact from 4 to 5\n  * kubevirt: modprobe for virtio_blk; remove dracut preload\n  * kubevirt: Add NoCloud network configuration support\n  * kubevirt: Support config drive network data\n  * kubevirt: Refactor the provider to follow the proxmoxve structure\n  * dracut: Add virtio_blk module preload to afterburn-network-kargs service\n  * docs: Add release notes\n  * cargo: Afterburn release 5.10.0\n- Version 5.10.0:\n  * docs/release-notes: update for release 5.10.0\n  * cargo: update dependencies\n  * microsoft/azure: Add XML attribute alias for serde-xml-rs Fedora compat\n  * docs/release-notes: Add entry for Azure SharedConfig XML parsing fix\n  * microsoft/azure: Fix SharedConfig parsing of XML attributes\n  * microsoft/azure: Mock goalstate.SharedConfig output in tests\n  * providers/azure: switch SSH key retrieval from certs endpoint to IMDS\n  * build(deps): bump the build group with 8 updates\n  * build(deps): bump slab from 0.4.10 to 0.4.11\n  * build(deps): bump actions/checkout from 4 to 5\n  * upcloud: implement UpCloud provider\n  * build(deps): bump the build group with 4 updates\n","affected":[{"package":{"name":"afterburn","ecosystem":"SUSE:Linux Enterprise Micro 5.3","purl":"pkg:rpm/suse/afterburn&distro=SUSE%20Linux%20Enterprise%20Micro%205.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.10.0.git73.b97f772-150400.3.6.1"}]}],"ecosystem_specific":{"binaries":[{"afterburn":"5.10.0.git73.b97f772-150400.3.6.1","afterburn-dracut":"5.10.0.git73.b97f772-150400.3.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2976-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20262976-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270175"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270483"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270555"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270651"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270787"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270817"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270886"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270949"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271348"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25541"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41676"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41677"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41678"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41681"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41898"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42327"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44662"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45784"}]}