SUSE-SU-2026:4417-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20264417-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4417-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:4417-1
Upstream
CVE (2)
Related
Published
2026-10-02T09:20:18Z
Modified
2026-10-02T18:30:40Z
Summary
Security update for helm
Details

This update for helm fixes the following issues:

  • CVE-2026-85731: oras.land/oras-go/v2: arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (bsc#1281104).
  • CVE-2026-85732: oras.land/oras-go/v2: blind SSRF via unvalidated Link header URL in pagination allows internal network probing (bsc#1281112).

Changes for helm:

  • Update to version 3.22.0:
  • chore(deps): bump the k8s-io group across 1 directory with 6 updates
  • bump version to 3.22 (#32606)
  • fix: set [pull,push] scope when helm push to a registry(use token auth) (backport) (#32362)
  • chore(deps): bump the k8s-io group with 7 updates (#32573)
  • chore(deps): bump github.com/stretchr/testify from 1.12.0 to 1.12.1 (#32563)
  • chore(deps): bump github.com/stretchr/testify from 1.11.1 to 1.12.0 (#32554)
  • chore(deps): bump golang.org/x/crypto from 0.54.0 to 0.55.0 (#32542)
  • [dev-v3 backport] deps: bump google.golang.org/grpc@v1.82.1 for GO-2026-6061 (#32536)
  • fix: bump go.opentelemetry.io/otel@v1.44.0 for GO-2026-5158 (#32535)
  • chore(deps): bump github.com/santhosh-tekuri/jsonschema/v6
  • fix(provenance): migrate to ProtonMail/go-crypto to resolve GO-2026-5932
  • chore(deps): bump the k8s-io group with 7 updates
  • chore(deps): bump github/codeql-action/upload-sarif (#32449)
  • chore(deps): bump github/codeql-action/analyze from 4.37.1 to 4.37.2
  • chore(deps): bump github/codeql-action/autobuild from 4.37.1 to 4.37.2
  • chore(deps): bump github/codeql-action/init from 4.37.1 to 4.37.2
  • chore(deps): bump github/codeql-action/autobuild from 4.37.0 to 4.37.1 (#32381)
  • chore(deps): bump github/codeql-action/upload-sarif (#32382)
  • ci: auto-label PRs targeting dev-v3 (#32340)
  • chore(deps): bump oras.land/oras-go/v2 from 2.6.1 to 2.6.2 (#32331)
  • chore(deps): bump github.com/mattn/go-shellwords from 1.0.13 to 1.0.14 (#32332)
  • chore(deps): bump github/codeql-action/analyze from 3.26.6 to 4.37.0 (#32357)
  • chore(deps): bump github/codeql-action/upload-sarif (#32360)
  • chore(deps): bump github/codeql-action/init from 3.26.6 to 4.37.0 (#32359)
  • chore(deps): bump golang/govulncheck-action from 1.0.4 to 1.1.0 (#32356)
  • chore(deps): bump golangci/golangci-lint-action from 6.1.1 to 9.3.0 (#32354)
  • chore(deps): bump ossf/scorecard-action from 2.4.0 to 2.4.3 (#32353)
  • chore(deps): bump golang.org/x/text from 0.38.0 to 0.40.0 (#32310)
  • chore(deps): bump golang.org/x/crypto from 0.53.0 to 0.54.0 (#32308)
  • chore(deps): bump golang.org/x/term from 0.44.0 to 0.45.0 (#32306)
  • fix(engine): prevent Files.Lines panic on empty file
  • fix: drop containerd v1 dep to resolve govulncheck CVEs
  • chore(deps): bump github.com/containerd/containerd from 1.7.32 to 1.7.33
  • chore(deps): bump github.com/cyphar/filepath-securejoin
  • chore(deps): bump the k8s-io group with 2 updates
  • chore(deps): bump the k8s-io group across 1 directory with 2 updates
  • fix(registry): keep credentials on plain-HTTP fallback with oras-go v2.6.1
  • chore(deps): bump oras.land/oras-go/v2 from 2.6.0 to 2.6.1
  • chore(deps): bump golang.org/x/crypto from 0.52.0 to 0.53.0
  • chore(deps): bump golang.org/x/term from 0.43.0 to 0.44.0
  • chore(deps): bump golang.org/x/text from 0.37.0 to 0.38.0
  • ci: bump golangci-lint to v2.11.3 for go 1.26
  • chore(deps): bump github.com/lib/pq from 1.11.2 to 1.12.3
  • chore(deps): bump github.com/distribution/distribution/v3
  • chore(deps): bump github.com/containerd/containerd from 1.7.30 to 1.7.32
  • chore(deps): bump github.com/Masterminds/semver/v3 from 3.4.0 to 3.5.0
  • chore(deps): bump github.com/mattn/go-shellwords from 1.0.12 to 1.0.13
  • chore(deps): bump golang.org/x/crypto from 0.51.0 to 0.52.0
  • fix(deps): bump golang.org/x/net to v0.55.0 to address GO-2026-5026
  • chore(deps): bump k8s.io/klog/v2 from 2.130.1 to 2.140.0
  • chore(deps): bump golang.org/x/text from 0.35.0 to 0.37.0
  • [v3] Bump to version v3.21 (#32103)
  • [v3 backport] Fix rollback for missing resources
  • fix(action): avoid nil REST client getter panic when installing CRDs
References

Affected packages

SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS
helm

Package

Name
helm
Purl
pkg:rpm/suse/helm&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.22.0-150000.1.99.1

Ecosystem specific

{
    "binaries": [
        {
            "helm": "3.22.0-150000.1.99.1",
            "helm-bash-completion": "3.22.0-150000.1.99.1",
            "helm-zsh-completion": "3.22.0-150000.1.99.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4417-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS
helm

Package

Name
helm
Purl
pkg:rpm/suse/helm&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.22.0-150000.1.99.1

Ecosystem specific

{
    "binaries": [
        {
            "helm": "3.22.0-150000.1.99.1",
            "helm-bash-completion": "3.22.0-150000.1.99.1",
            "helm-zsh-completion": "3.22.0-150000.1.99.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4417-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS
helm

Package

Name
helm
Purl
pkg:rpm/suse/helm&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.22.0-150000.1.99.1

Ecosystem specific

{
    "binaries": [
        {
            "helm": "3.22.0-150000.1.99.1",
            "helm-bash-completion": "3.22.0-150000.1.99.1",
            "helm-zsh-completion": "3.22.0-150000.1.99.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4417-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS
helm

Package

Name
helm
Purl
pkg:rpm/suse/helm&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.22.0-150000.1.99.1

Ecosystem specific

{
    "binaries": [
        {
            "helm": "3.22.0-150000.1.99.1",
            "helm-bash-completion": "3.22.0-150000.1.99.1",
            "helm-zsh-completion": "3.22.0-150000.1.99.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4417-1.json"
SUSE:Linux Enterprise Micro 5.5
helm

Package

Name
helm
Purl
pkg:rpm/suse/helm&distro=SUSE%20Linux%20Enterprise%20Micro%205.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.22.0-150000.1.99.1

Ecosystem specific

{
    "binaries": [
        {
            "helm": "3.22.0-150000.1.99.1",
            "helm-bash-completion": "3.22.0-150000.1.99.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4417-1.json"
SUSE:Linux Enterprise Module for Containers 15 SP7
helm

Package

Name
helm
Purl
pkg:rpm/suse/helm&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.22.0-150000.1.99.1

Ecosystem specific

{
    "binaries": [
        {
            "helm": "3.22.0-150000.1.99.1",
            "helm-bash-completion": "3.22.0-150000.1.99.1",
            "helm-zsh-completion": "3.22.0-150000.1.99.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4417-1.json"
SUSE:Linux Enterprise Module for Package Hub 15 SP7
helm

Package

Name
helm
Purl
pkg:rpm/suse/helm&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.22.0-150000.1.99.1

Ecosystem specific

{
    "binaries": [
        {
            "helm-fish-completion": "3.22.0-150000.1.99.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4417-1.json"
SUSE:Linux Enterprise Server 15 SP4-LTSS
helm

Package

Name
helm
Purl
pkg:rpm/suse/helm&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.22.0-150000.1.99.1

Ecosystem specific

{
    "binaries": [
        {
            "helm": "3.22.0-150000.1.99.1",
            "helm-bash-completion": "3.22.0-150000.1.99.1",
            "helm-zsh-completion": "3.22.0-150000.1.99.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4417-1.json"
SUSE:Linux Enterprise Server 15 SP5-LTSS
helm

Package

Name
helm
Purl
pkg:rpm/suse/helm&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.22.0-150000.1.99.1

Ecosystem specific

{
    "binaries": [
        {
            "helm": "3.22.0-150000.1.99.1",
            "helm-bash-completion": "3.22.0-150000.1.99.1",
            "helm-zsh-completion": "3.22.0-150000.1.99.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4417-1.json"
SUSE:Linux Enterprise Server 15 SP6-LTSS
helm

Package

Name
helm
Purl
pkg:rpm/suse/helm&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.22.0-150000.1.99.1

Ecosystem specific

{
    "binaries": [
        {
            "helm": "3.22.0-150000.1.99.1",
            "helm-bash-completion": "3.22.0-150000.1.99.1",
            "helm-zsh-completion": "3.22.0-150000.1.99.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4417-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP4
helm

Package

Name
helm
Purl
pkg:rpm/suse/helm&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.22.0-150000.1.99.1

Ecosystem specific

{
    "binaries": [
        {
            "helm": "3.22.0-150000.1.99.1",
            "helm-bash-completion": "3.22.0-150000.1.99.1",
            "helm-zsh-completion": "3.22.0-150000.1.99.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4417-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP5
helm

Package

Name
helm
Purl
pkg:rpm/suse/helm&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.22.0-150000.1.99.1

Ecosystem specific

{
    "binaries": [
        {
            "helm": "3.22.0-150000.1.99.1",
            "helm-bash-completion": "3.22.0-150000.1.99.1",
            "helm-zsh-completion": "3.22.0-150000.1.99.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4417-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP6
helm

Package

Name
helm
Purl
pkg:rpm/suse/helm&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.22.0-150000.1.99.1

Ecosystem specific

{
    "binaries": [
        {
            "helm": "3.22.0-150000.1.99.1",
            "helm-bash-completion": "3.22.0-150000.1.99.1",
            "helm-zsh-completion": "3.22.0-150000.1.99.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4417-1.json"