FlawAtlas
Search the atlas
OPENSUSE-SU-2026:20902-1 Not scored

Security update for keybase-client

This update for keybase-client fixes the following issues: Changes in keybase-client: - golang.org/x/crypto/ssh: Fixed multiple issues: CVE-2026-39827, CVE-2026-39834, CVE-2026-39828, CVE-2026-39829, CVE-2026-39831, CVE-2026-42508, CVE-2026-39833, CVE-2026-39830, CVE-2026-39832, CVE-2026-46597, CVE-2026-46598, CVE-2026-46595, CVE-2026-39835 (boo#1266158) - CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (boo#1266596). - Update to version 6.6.2 * Improve git default branch handling - CVE-2026-33809: golang.org/x/image/tiff: excessive resource consumption due to large allocation attempt when decoding maliciously crafted TIFF file (bsc#1260696) - Switch to go1.25 as required by update go image library. - Update to version 6.6.0 * Various bug fixes and performance improvements - CVE-2026-26958: filippo.io/edwards25519: failure to initialize receiver in MultiScalarMult can produce invalid results and lead to undefined behavior (bsc#1258591). - CVE-2025-47914: golang.org/x/crypto/ssh/agent: non validated message size can cause a panic due to an out of bounds read (bsc#1254023). - CVE-2025-58181: keybase-client: golang.org/x/crypto/ssh: invalidated number of mechanisms can cause unbounded memory consumption (bsc#1253864). - CVE-2025-47913: keybase-client: golang.org/x/crypto/ssh/agent: client process termination when receiving an unexpected message type in response to a key listing or signing request (bsc#1253563). - Update to version 6.5.1 * Fix team deletion not working * Chat attachments improvements * Miscellaneous bugfixes

Exploit probability Not scored
Published June 3, 2026
Required by Not available
Last source change June 6, 2026

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities openSUSE-SU-2026:20902-1

This update for keybase-client fixes the following issues: Changes in keybase-client: - golang.org/x/crypto/ssh: Fixed multiple issues: CVE-2026-39827, CVE-2026-39834, CVE-2026-39828, CVE-2026-39829, CVE-2026-39831, CVE-2026-42508, CVE-2026-39833, CVE-2026-39830, CVE-2026-39832, CVE-2026-46597, CVE-2026-46598, CVE-2026-46595, CVE-2026-39835 (boo#1266158) - CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (boo#1266596). - Update to version 6.6.2 * Improve git default branch handling - CVE-2026-33809: golang.org/x/image/tiff: excessive resource consumption due to large allocation attempt when decoding maliciously crafted TIFF file (bsc#1260696) - Switch to go1.25 as required by update go image library. - Update to version 6.6.0 * Various bug fixes and performance improvements - CVE-2026-26958: filippo.io/edwards25519: failure to initialize receiver in MultiScalarMult can produce invalid results and lead to undefined behavior (bsc#1258591). - CVE-2025-47914: golang.org/x/crypto/ssh/agent: non validated message size can cause a panic due to an out of bounds read (bsc#1254023). - CVE-2025-58181: keybase-client: golang.org/x/crypto/ssh: invalidated number of mechanisms can cause unbounded memory consumption (bsc#1253864). - CVE-2025-47913: keybase-client: golang.org/x/crypto/ssh/agent: client process termination when receiving an unexpected message type in response to a key listing or signing request (bsc#1253563). - Update to version 6.5.1 * Fix team deletion not working * Chat attachments improvements * Miscellaneous bugfixes

View original source

05 / REFERENCES

Further evidence