FlawAtlas
Search the atlas
SUSE-SU-2026:1411-1 Not scored

Security update for terraform-provider-local, terraform-provider-random, terraform-provider-tls

This update for terraform-provider-local, terraform-provider-random, terraform-provider-tls fixes the following issue: - CVE-2026-25934: github.com/go-git/go-git/v5: improper verification of data integrity values for .pack and .idx files that can lead to the consumption of corrupted files (bsc#1258097). - CVE-2026-33186: fix authorization bypass in grpc-go due to improper validation of the HTTP/2 :path pseudo-header (bsc#1260218)

Exploit probability Not scored
Published April 16, 2026
Required by Not available
Last source change April 17, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Module for Public Cloud 15 SP4 terraform-provider-local
SUSE:Linux Enterprise Module for Public Cloud 15 SP4 terraform-provider-null
SUSE:Linux Enterprise Module for Public Cloud 15 SP4 terraform-provider-random
SUSE:Linux Enterprise Module for Public Cloud 15 SP4 terraform-provider-tls
SUSE:Linux Enterprise Module for Public Cloud 15 SP5 terraform-provider-local
SUSE:Linux Enterprise Module for Public Cloud 15 SP5 terraform-provider-null
SUSE:Linux Enterprise Module for Public Cloud 15 SP5 terraform-provider-random
SUSE:Linux Enterprise Module for Public Cloud 15 SP5 terraform-provider-tls
openSUSE:Leap 15.6 terraform-provider-local
openSUSE:Leap 15.6 terraform-provider-null
openSUSE:Leap 15.6 terraform-provider-random
openSUSE:Leap 15.6 terraform-provider-tls

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:1411-1

This update for terraform-provider-local, terraform-provider-random, terraform-provider-tls fixes the following issue: - CVE-2026-25934: github.com/go-git/go-git/v5: improper verification of data integrity values for .pack and .idx files that can lead to the consumption of corrupted files (bsc#1258097). - CVE-2026-33186: fix authorization bypass in grpc-go due to improper validation of the HTTP/2 :path pseudo-header (bsc#1260218)

View original source

05 / REFERENCES

Further evidence