{"schema_version":"1.7.5","id":"SUSE-SU-2026:3417-1","published":"2026-07-30T07:06:33Z","modified":"2026-07-30T17:15:08.160681872Z","related":["CVE-2026-39821","CVE-2026-56852"],"upstream":["CVE-2026-39821","CVE-2026-56852"],"summary":"Security update for apptainer","details":"This update for apptainer fixes the following issues:\n\n- CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation\n  bypass and privilege escalation (bsc#1266656).\n- CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272115).\n\nChanges for apptainer:\n\n- Update apptainer to version 1.5.3:\n\n * If the ptrace() system call does not work while building an image as\n an unprivileged user, skip using PRoot to preserve file ownership and\n print an INFO message.\n * Bind getopt from the host when using fakeroot command mode, to make\n the fakeroot command work with base containers which no longer contain\n getopt by default.\n * Extended the mksquashfs segmentation fault workaround for cases\n where mksquashfs uses many processor cores.\n","affected":[{"package":{"name":"apptainer","ecosystem":"SUSE:Linux Enterprise Module for HPC 15 SP7","purl":"pkg:rpm/suse/apptainer&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.5.3-150600.4.34.2"}]}],"ecosystem_specific":{"binaries":[{"apptainer":"1.5.3-150600.4.34.2","apptainer-sle15_7":"1.5.3-150600.4.34.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3417-1.json"}},{"package":{"name":"apptainer","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP7","purl":"pkg:rpm/suse/apptainer&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.5.3-150600.4.34.2"}]}],"ecosystem_specific":{"binaries":[{"apptainer":"1.5.3-150600.4.34.2","apptainer-suid":"1.5.3-150600.4.34.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3417-1.json"}},{"package":{"name":"apptainer","ecosystem":"SUSE:Linux Enterprise Server 15 SP6-LTSS","purl":"pkg:rpm/suse/apptainer&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.5.3-150600.4.34.2"}]}],"ecosystem_specific":{"binaries":[{"apptainer":"1.5.3-150600.4.34.2","apptainer-sle15_6":"1.5.3-150600.4.34.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3417-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20263417-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266656"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272115"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39821"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56852"}]}