{"schema_version":"1.7.5","id":"openSUSE-SU-2026:20902-1","published":"2026-06-03T17:44:01Z","modified":"2026-06-06T18:24:23.494336976Z","related":["CVE-2025-47913","CVE-2025-47914","CVE-2025-58181","CVE-2026-26958","CVE-2026-33809","CVE-2026-39821","CVE-2026-39827","CVE-2026-39828","CVE-2026-39829","CVE-2026-39830","CVE-2026-39831","CVE-2026-39832","CVE-2026-39833","CVE-2026-39834","CVE-2026-39835","CVE-2026-42508","CVE-2026-46595","CVE-2026-46597","CVE-2026-46598"],"upstream":["CVE-2025-47913","CVE-2025-47914","CVE-2025-58181","CVE-2026-26958","CVE-2026-33809","CVE-2026-39821","CVE-2026-39827","CVE-2026-39828","CVE-2026-39829","CVE-2026-39830","CVE-2026-39831","CVE-2026-39832","CVE-2026-39833","CVE-2026-39834","CVE-2026-39835","CVE-2026-42508","CVE-2026-46595","CVE-2026-46597","CVE-2026-46598"],"summary":"Security update for keybase-client","details":"This update for keybase-client fixes the following issues:\n\nChanges in keybase-client:\n\n- golang.org/x/crypto/ssh: Fixed multiple issues:\n  CVE-2026-39827, CVE-2026-39834, CVE-2026-39828, CVE-2026-39829, CVE-2026-39831,\n  CVE-2026-42508, CVE-2026-39833, CVE-2026-39830, CVE-2026-39832, CVE-2026-46597,\n  CVE-2026-46598, CVE-2026-46595, CVE-2026-39835 (boo#1266158)\n- CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels\n  allows for validation bypass and privilege escalation (boo#1266596).\n\n- Update to version 6.6.2\n  * Improve git default branch handling\n\n- CVE-2026-33809: golang.org/x/image/tiff: excessive resource consumption due to\n  large allocation attempt when decoding maliciously crafted TIFF file (bsc#1260696)\n- Switch to go1.25 as required by update go image library.\n\n- Update to version 6.6.0\n  * Various bug fixes and performance improvements\n\n- CVE-2026-26958: filippo.io/edwards25519: failure to initialize receiver in MultiScalarMult\n  can produce invalid results and lead to undefined behavior (bsc#1258591).\n- CVE-2025-47914: golang.org/x/crypto/ssh/agent: non validated message size can cause a panic\n  due to an out of bounds read (bsc#1254023).\n- CVE-2025-58181: keybase-client: golang.org/x/crypto/ssh: invalidated number of mechanisms\n  can cause unbounded memory consumption (bsc#1253864).\n- CVE-2025-47913: keybase-client: golang.org/x/crypto/ssh/agent: client process termination\n  when receiving an unexpected message type in response to a key listing or signing request (bsc#1253563).\n\n- Update to version 6.5.1\n  * Fix team deletion not working\n  * Chat attachments improvements\n  * Miscellaneous bugfixes\n","references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1253563"},{"type":"REPORT","url":"https://bugzilla.suse.com/1253864"},{"type":"REPORT","url":"https://bugzilla.suse.com/1254023"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258591"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260696"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266158"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266596"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-47913"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-47914"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-58181"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-26958"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33809"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39821"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39827"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39828"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39829"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39830"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39831"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39832"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39833"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39834"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39835"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42508"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46595"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46597"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46598"}]}