SUSE-SU-2026:2976-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20262976-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2976-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:2976-1
Upstream
CVE (9)
Related
Published
2026-07-14T11:39:57Z
Modified
2026-07-15T10:00:09Z
Summary
Security update for afterburn
Details

This update for afterburn fixes the following issues

Update to version 5.10.0.git73.b97f772.

Security issues fixed:

  • CVE-2026-41676: openssl: Deriver:derive and PkeyCtxRef:derive can overflow short buffers on OpenSSL 1.1.1 (bsc#1270175).
  • CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length (bsc#1270555).
  • CVE-2026-41678: openssl: incorrect bounds assertion in aes::unwrap_key() can lead to OOB write (bsc#1270651).
  • CVE-2026-41681: openssl: MdCtxRef::digest_final() writes past caller buffer with no length check (bsc#1270787).
  • CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory to network peers (bsc#1270817).
  • CVE-2026-42327: openssl: undefined behavior in X509Ref::ocsp_responders when processing certificates with non-UTF-8 OCSP URLs (bsc#1270483).
  • CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key-wrap-with-padding (bsc#1270886).
  • CVE-2026-45784: openssl: out-of-bounds write in CipherCtxRef::cipher_update_inplace for AES-KW-PAD ciphers (bsc#1270949).
  • CVE-2026-25541: bytes: integer overflow in BytesMut:reserve can lead to undefined behavior and crashes (bsc#1271348).

Other updates and bugfixes:

  • Version 5.10.0.git73.b97f772:
  • Version 5.10.0.git70.9cc2a7b:
    • build(deps): bump openssl from 0.10.78 to 0.10.79
    • providers/hetzner: Add the HETZNER_PUBLIC_IPV6 attribute
    • providers/hetzner: Add support for network configuration
    • build(deps): bump rustls-webpki from 0.103.10 to 0.103.13
    • build(deps): bump openssl from 0.10.73 to 0.10.78
    • docs: Add AGENTS.md and CLAUDE.md for AI coding assistants
    • build(deps): bump rand from 0.9.2 to 0.9.4
    • opencode: add skills for provider scaffolding and release automation
    • ibmcloud-classic: Add missing network_id to fixture
    • kubevirt: Support static gateway and DNS with DHCP
    • build(deps): bump rustls-webpki from 0.103.6 to 0.103.10
    • fix(proxmoxve): Define DNS entries for every interface
    • Makefile: download 90-afterburn-authorized-keys-file.conf for rpm building
    • Sync repo templates ⚙
    • build(deps): bump bytes from 1.10.1 to 1.11.1
    • util/dhcp: Fix clippy lints
    • build(deps): bump actions/checkout from 4 to 6
    • build(deps): bump actions/upload-artifact from 4 to 5
    • kubevirt: modprobe for virtio_blk; remove dracut preload
    • kubevirt: Add NoCloud network configuration support
    • kubevirt: Support config drive network data
    • kubevirt: Refactor the provider to follow the proxmoxve structure
    • dracut: Add virtio_blk module preload to afterburn-network-kargs service
    • docs: Add release notes
    • cargo: Afterburn release 5.10.0
  • Version 5.10.0:
    • docs/release-notes: update for release 5.10.0
    • cargo: update dependencies
    • microsoft/azure: Add XML attribute alias for serde-xml-rs Fedora compat
    • docs/release-notes: Add entry for Azure SharedConfig XML parsing fix
    • microsoft/azure: Fix SharedConfig parsing of XML attributes
    • microsoft/azure: Mock goalstate.SharedConfig output in tests
    • providers/azure: switch SSH key retrieval from certs endpoint to IMDS
    • build(deps): bump the build group with 8 updates
    • build(deps): bump slab from 0.4.10 to 0.4.11
    • build(deps): bump actions/checkout from 4 to 5
    • upcloud: implement UpCloud provider
    • build(deps): bump the build group with 4 updates
References

Affected packages

SUSE:Linux Enterprise Micro 5.3 / afterburn

Package

Name
afterburn
Purl
pkg:rpm/suse/afterburn&distro=SUSE%20Linux%20Enterprise%20Micro%205.3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.10.0.git73.b97f772-150400.3.6.1

Ecosystem specific

{
    "binaries":  [
        {
            "afterburn":  "5.10.0.git73.b97f772-150400.3.6.1",
            "afterburn-dracut":  "5.10.0.git73.b97f772-150400.3.6.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2976-1.json"