{"schema_version":"1.7.5","id":"openSUSE-SU-2026:21499-1","published":"2026-07-29T09:24:08Z","modified":"2026-07-31T18:24:09.384914511Z","related":["CVE-2026-39821","CVE-2026-56852"],"upstream":["CVE-2026-39821","CVE-2026-56852"],"summary":"Security update for apptainer","details":"This update for apptainer fixes the following issues:\n\nChanges in apptainer:\n\n- Update to version 1.5.3:\n  * If the ptrace() system call does not work while building an image as\n    an unprivileged user, skip using PRoot to preserve file ownership and\n    print an INFO message.\n  * Bind getopt from the host when using fakeroot command mode, to make\n    the fakeroot command work with base containers which no longer contain\n    getopt by default.\n  * Update fixes CVE-2026-56852 (GO-2026-5970) (bsc#1272115)\n    golang.org/x/text/unicode/norm:\n    A norm.Iter can enter an infinite loop when handling input\n    containing invalid UTF-8 bytes.\n\n- Update to version 1.5.2:\n  * Extended the mksquashfs segmentation fault workaround for cases\n    where mksquashfs uses many processor cores.\n\n- Update the golang.org/x/net dependency to version v0.57.0\n  to fix CVE-2026-39821 for good (bsc#1266656).\n  The fix in v0.55.0 only applied to Unicode versions >=16.0.0\n  which aren't yet available on any Golang versions released.\n","affected":[{"package":{"name":"apptainer","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/apptainer&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.5.3-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"apptainer":"1.5.3-bp160.1.1","apptainer-leap":"1.5.3-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21499-1.json"}}],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266656"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272115"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39821"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56852"}]}