openSUSE-SU-2026:21824-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21824-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2026:21824-1
Upstream
CVE (39)
Related
Published
2026-09-09T15:12:11Z
Modified
2026-09-12T18:23:35Z
Summary
Security update for containerized-data-importer1.65
Details

This update for containerized-data-importer1.65 fixes the following issues:

  • CVE-2025-22869: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh (bsc#1239322).
  • CVE-2025-22870: golang.org/x/net/proxy: proxy bypass using IPv6 zone IDs (bsc#1238699).
  • CVE-2025-22872: golang.org/x/net/html: incorrectly interpreted tags can cause content to be placed wrong scope during DOM construction (bsc#1241838).
  • CVE-2025-47911: golang.org/x/net/html: various algorithms with quadratic complexity when parsing HTML documents (bsc#1251495).
  • CVE-2025-47913: client process termination when receiving an unexpected message type in response to a key listing or (bsc#1253506).
  • CVE-2025-47914: non validated message size can cause a panic due to an out of bounds read (bsc#1253967).
  • CVE-2025-58058: github.com/ulikunitz/xz: github.com/ulikunitz/xz leaks memory (bsc#1248946).
  • CVE-2025-58181: invalidated number of mechanisms can cause unbounded memory consumption (bsc#1253784).
  • CVE-2025-58190: golang.org/x/net/html: excessive memory consumption by html.ParseFragment when processing specially crafted input (bsc#1251689).
  • CVE-2026-25680,CVE-2026-25681,CVE-2026-27136,CVE-2026-42502,CVE-2026-42506: golang.org/x/net/html: multiple issues when parsing HTML files (bsc#1267176).
  • CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 :path pseudo- header (bsc#1260295).
  • CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265799).
  • CVE-2026-34986: github.com/go-jose/go-jose/v3: crafted JWE input with a missing encrypted key can lead to a denial of service (bsc#1262952).
  • CVE-2026-35469: github.com/moby/spdystream: memory amplification in SPDY frame parsing leads to denial of service (bsc#1262269).
  • CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266639).
  • CVE-2026-39827,CVE-2026-39828,CVE-2026-39829,CVE-2026-39830,CVE-2026-39831,CVE-2026-39832,CVE-2026-39833, CVE-2026-39834,CVE-2026-39835,CVE-2026-42508,CVE-2026-46595,CVE-2026-46597, CVE-2026-46598: multiple issues in golang.org/x/crypto/ssh (bsc#1266179).
  • CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276687).
  • CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272064).
  • CVE-2026-56854,CVE-2026-56855,CVE-2026-78662: golang.org/x/crypto/ssh: authentication bypass and deadlocks in the crypto/ssh library (bsc#1278621).
  • CVE-2026-84303: google.golang.org/grpc: xDS RBAC HTTP filter implementation issue allows for bypass of authorization policies via mixed-case or canonical-case header matches (bsc#1279315).
  • CVE-2026-84304: google.golang.org/grpc: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1279234).
References

Affected packages

openSUSE:Leap 16.0 / containerized-data-importer1.65

Package

Name
containerized-data-importer1.65
Purl
pkg:rpm/opensuse/containerized-data-importer1.65&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.65.0-160000.3.1

Ecosystem specific

{
    "binaries":  [
        {
            "containerized-data-importer1.65-api":  "1.65.0-160000.3.1",
            "containerized-data-importer1.65-cloner":  "1.65.0-160000.3.1",
            "containerized-data-importer1.65-controller":  "1.65.0-160000.3.1",
            "containerized-data-importer1.65-importer":  "1.65.0-160000.3.1",
            "containerized-data-importer1.65-manifests":  "1.65.0-160000.3.1",
            "containerized-data-importer1.65-operator":  "1.65.0-160000.3.1",
            "containerized-data-importer1.65-uploadproxy":  "1.65.0-160000.3.1",
            "containerized-data-importer1.65-uploadserver":  "1.65.0-160000.3.1",
            "obs-service-cdi1.65_containers_meta":  "1.65.0-160000.3.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21824-1.json"