openSUSE-SU-2026:21793-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21793-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2026:21793-1
Upstream
CVE (6)
Related
Published
2026-09-03T12:32:31Z
Modified
2026-09-09T18:23:35Z
Summary
Security update for hauler
Details

This update for hauler fixes the following issues:

Changes in hauler:

  • update to 2.1.0 (bsc#1265425, CVE-2026-41888):

    • v2.1.0 is a minor release built on the containerd- native foundation laid down in v2.0.0. The headline is that hauler store sync and hauler store add are now fully concurrent, with signature verification pinned to digests and running in parallel too. Alongside that, this release adds an audit trail, a store integrity checker, store-to-manifest generation, private/insecure registry support across every pull path, and a set of fixes for containerd imports, chunked hauls, and Docker Hub reference handling.
    • Notable dependency bumps: Go → 1.26.6; containerd/v2 → 2.3.4; sigstore/cosign/v3 → 3.1.3; sigstore/sigstore → 1.10.9; go-containerregistry → 0.22.0; helm/v4 → 4.2.4; k8s.io libs (apimachinery, api, client-go) → 0.37.0; logrus → 1.10.2; docker/go-metrics → 0.1.0; sigstore/rekor → 1.5.4 (CVE resolution); plus x/mod and go-isatty.
  • update to 2.0.3 (bsc#1276124, CVE-2026-72817,CVE-2026-72815,CVE-2026-72816):

    • Bump k8s.io/apimachinery from 0.36.2 to 0.36.3 (backport #688)
    • Bump oras.land/oras-go/v2 from 2.6.1 to 2.6.2 in the go_modules group across 1 directory (backport #691)
    • fix for homebrew macOS binary quarantine (backport #690)
    • fix: process Helm deps before --add-images discovery (backport #703)
    • update hauler store remove to handle registry reference as part of string (backport #705)
    • fixed vuln for golang grpc
References

Affected packages

openSUSE:Leap 16.0 / hauler

Package

Name
hauler
Purl
pkg:rpm/opensuse/hauler&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.1.0-bp160.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "hauler":  "2.1.0-bp160.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21793-1.json"