FlawAtlas
Search the atlas
SUSE-SU-2026:0439-1 Not scored

Security update for apptainer

This update for apptainer fixes the following issues: Security fixes: - CVE-2024-45310: Fixed runc being tricked into creating empty files/directories on host (bsc#1257432) - CVE-2025-65105: Fixed security bypass due to disabling security options (bsc#1255462) - CVE-2025-47914: Fixed malformed constraint may cause denial of service in golang.org/x/crypto/ssh/agent (bsc#1253967) - CVE-2025-58181: Fixed unbounded memory consumption in golang.org/x/crypto/ssh (bsc#1253784) - CVE-2025-47913: Fixed potential denial of service in golang.org/x/crypto/ssh/agent (bsc#1253506) - CVE-2025-22872: Fixed incorrect Neutralization of Input During Web Page Generation in x/net (bsc#1241710) - CVE-2025-22870: Fixed HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net (bsc#1238611) - CVE-2025-22869: Fixed potential denial of service in golang.org/x/crypto (bsc#1239322) - CVE-2025-27144: Fixed DoS in go-jose Parsing in github.com/go-jose/go-jose (bsc#1237608) - CVE-2025-8556: Fixed missing and wrong validation can lead to incorrect results in github.com/cloudflare/circl Other fixes: - Update to 1.4.5

Exploit probability Not scored
Published February 11, 2026
Required by Not available
Last source change March 23, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Module for HPC 15 SP7 apptainer
SUSE:Linux Enterprise Module for HPC 15 SP7 squashfuse
SUSE:Linux Enterprise Server 15 SP6-LTSS apptainer
SUSE:Linux Enterprise Server 15 SP6-LTSS squashfuse
openSUSE:Leap 15.6 apptainer
openSUSE:Leap 15.6 squashfuse

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:0439-1

This update for apptainer fixes the following issues: Security fixes: - CVE-2024-45310: Fixed runc being tricked into creating empty files/directories on host (bsc#1257432) - CVE-2025-65105: Fixed security bypass due to disabling security options (bsc#1255462) - CVE-2025-47914: Fixed malformed constraint may cause denial of service in golang.org/x/crypto/ssh/agent (bsc#1253967) - CVE-2025-58181: Fixed unbounded memory consumption in golang.org/x/crypto/ssh (bsc#1253784) - CVE-2025-47913: Fixed potential denial of service in golang.org/x/crypto/ssh/agent (bsc#1253506) - CVE-2025-22872: Fixed incorrect Neutralization of Input During Web Page Generation in x/net (bsc#1241710) - CVE-2025-22870: Fixed HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net (bsc#1238611) - CVE-2025-22869: Fixed potential denial of service in golang.org/x/crypto (bsc#1239322) - CVE-2025-27144: Fixed DoS in go-jose Parsing in github.com/go-jose/go-jose (bsc#1237608) - CVE-2025-8556: Fixed missing and wrong validation can lead to incorrect results in github.com/cloudflare/circl Other fixes: - Update to 1.4.5

View original source

05 / REFERENCES

Further evidence