openSUSE-SU-2026:21824-1
Dashboard / Vulnerabilities / openSUSE-SU-2026:21824-1
openSUSE-SU-2026:21824-1
Summary: Security update for containerized-data-importer1.65
Details: This update for containerized-data-importer1.65 fixes the following issues: - CVE-2025-22869: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh (bsc#1239322). - CVE-2025-22870: golang.org/x/net/proxy: proxy bypass using IPv6 zone IDs (bsc#1238699). - CVE-2025-22872: golang.org/x/net/html: incorrectly interpreted tags can cause content to be placed wrong scope during DOM construction (bsc#1241838). - CVE-2025-47911: golang.org/x/net/html: various algorithms with quadratic complexity when parsing HTML documents (bsc#1251495). - CVE-2025-47913: client process termination when receiving an unexpected message type in response to a key listing or (bsc#1253506). - CVE-2025-47914: non validated message size can cause a panic due to an out of bounds read (bsc#1253967). - CVE-2025-58058: github.com/ulikunitz/xz: github.com/ulikunitz/xz leaks memory (bsc#1248946). - CVE-2025-58181: invalidated number of mechanisms can cause unbounded memory consumption (bsc#1253784). - CVE-2025-58190: golang.org/x/net/html: excessive memory consumption by `html.ParseFragment` when processing specially crafted input (bsc#1251689). - CVE-2026-25680,CVE-2026-25681,CVE-2026-27136,CVE-2026-42502,CVE-2026-42506: golang.org/x/net/html: multiple issues when parsing HTML files (bsc#1267176). - CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 :path pseudo- header (bsc#1260295). - CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265799). - CVE-2026-34986: github.com/go-jose/go-jose/v3: crafted JWE input with a missing encrypted key can lead to a denial of service (bsc#1262952). - CVE-2026-35469: github.com/moby/spdystream: memory amplification in SPDY frame parsing leads to denial of service (bsc#1262269). - CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266639). - CVE-2026-39827,CVE-2026-39828,CVE-2026-39829,CVE-2026-39830,CVE-2026-39831,CVE-2026-39832,CVE-2026-39833, CVE-2026-39834,CVE-2026-39835,CVE-2026-42508,CVE-2026-46595,CVE-2026-46597, CVE-2026-46598: multiple issues in golang.org/x/crypto/ssh (bsc#1266179). - CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276687). - CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272064). - CVE-2026-56854,CVE-2026-56855,CVE-2026-78662: golang.org/x/crypto/ssh: authentication bypass and deadlocks in the crypto/ssh library (bsc#1278621). - CVE-2026-84303: google.golang.org/grpc: xDS RBAC HTTP filter implementation issue allows for bypass of authorization policies via mixed-case or canonical-case header matches (bsc#1279315). - CVE-2026-84304: google.golang.org/grpc: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1279234).
References: , https://bugzilla.suse.com/1238699, https://bugzilla.suse.com/1239322, https://bugzilla.suse.com/1241838, https://bugzilla.suse.com/1248946, https://bugzilla.suse.com/1251495, https://bugzilla.suse.com/1251689, https://bugzilla.suse.com/1253506, https://bugzilla.suse.com/1253784, https://bugzilla.suse.com/1253967, https://bugzilla.suse.com/1260295, https://bugzilla.suse.com/1262269, https://bugzilla.suse.com/1262952, https://bugzilla.suse.com/1265799, https://bugzilla.suse.com/1266179, https://bugzilla.suse.com/1266639, https://bugzilla.suse.com/1267176, https://bugzilla.suse.com/1272064, https://bugzilla.suse.com/1276687, https://bugzilla.suse.com/1278621, https://bugzilla.suse.com/1279234, https://bugzilla.suse.com/1279315, https://www.suse.com/security/cve/CVE-2025-22869, https://www.suse.com/security/cve/CVE-2025-22870, https://www.suse.com/security/cve/CVE-2025-22872, https://www.suse.com/security/cve/CVE-2025-47911, https://www.suse.com/security/cve/CVE-2025-47913, https://www.suse.com/security/cve/CVE-2025-47914, https://www.suse.com/security/cve/CVE-2025-58058, https://www.suse.com/security/cve/CVE-2025-58181, https://www.suse.com/security/cve/CVE-2025-58190, https://www.suse.com/security/cve/CVE-2026-25680, https://www.suse.com/security/cve/CVE-2026-25681, https://www.suse.com/security/cve/CVE-2026-27136, https://www.suse.com/security/cve/CVE-2026-33186, https://www.suse.com/security/cve/CVE-2026-33814, https://www.suse.com/security/cve/CVE-2026-34986, https://www.suse.com/security/cve/CVE-2026-35469, https://www.suse.com/security/cve/CVE-2026-39821, https://www.suse.com/security/cve/CVE-2026-39827, https://www.suse.com/security/cve/CVE-2026-39828, https://www.suse.com/security/cve/CVE-2026-39829, https://www.suse.com/security/cve/CVE-2026-39830, https://www.suse.com/security/cve/CVE-2026-39831, https://www.suse.com/security/cve/CVE-2026-39832, https://www.suse.com/security/cve/CVE-2026-39833, https://www.suse.com/security/cve/CVE-2026-39834, https://www.suse.com/security/cve/CVE-2026-39835, https://www.suse.com/security/cve/CVE-2026-41178, https://www.suse.com/security/cve/CVE-2026-42502, https://www.suse.com/security/cve/CVE-2026-42506, https://www.suse.com/security/cve/CVE-2026-42508, https://www.suse.com/security/cve/CVE-2026-46595, https://www.suse.com/security/cve/CVE-2026-46597, https://www.suse.com/security/cve/CVE-2026-46598, https://www.suse.com/security/cve/CVE-2026-56852, https://www.suse.com/security/cve/CVE-2026-56854, https://www.suse.com/security/cve/CVE-2026-56855, https://www.suse.com/security/cve/CVE-2026-78662, https://www.suse.com/security/cve/CVE-2026-84303, https://www.suse.com/security/cve/CVE-2026-84304
Affected packages
Package
Name: containerized-data-importer1.65
Purl: pkg:rpm/opensuse/containerized-data-importer1.65&distro=openSUSE%20Leap%2016.0
Affected ranges
Type: ECOSYSTEM
Events:
