FlawAtlas
Search the atlas
SUSE-SU-2026:3056-1 Not scored

Security update for terraform-provider-aws, terraform-provider-azurerm, terraform-provider-external, terraform-provider-google, terraform-provider-helm, terraform-provider-kubernetes, terraform-provider-local, terraform-provider-null, terraform-provider-random, terraform-provider-tls

This update for terraform-provider-aws, terraform-provider-azurerm, terraform-provider-external, terraform-provider-google, terraform-provider-helm, terraform-provider-kubernetes, terraform-provider-local, terraform-provider-null, terraform-provider-random, terraform-provider-tls fixes the following issues - CVE-2022-41723: go1.19,go1.20: net/http2: quadratic complexity in HPACK decoding (bsc#1208300). - CVE-2025-22872: golang.org/x/net/html: incorrectly interpreted tags can cause content to be placed wrong scope during DOM construction (bsc#1241728). - CVE-2025-32386: helm: specially crafted chart archive can cause OOM termination (bsc#1241030). - CVE-2025-32387: helm: specially crafted JSON schema can cause a stack overflow (bsc#1241033). - CVE-2025-47911: golang.org/x/net/html: various algorithms have quadratic complexity when parsing HTML documents (bsc#1251365). - CVE-2025-47913: golang.org/x/crypto/ssh/agent: client process termination when receiving an unexpected message type in response to a key listing or signing request (bsc#1253508 bsc#1253517). - CVE-2025-47914: golang.org/x/crypto/ssh/agent: non validated message size can cause a panic due to an out of bounds read (bsc#1253980 bsc#1253983). - CVE-2025-58181: golang.org/x/crypto/ssh: invalidated number of mechanisms can cause unbounded memory consumption (bsc#1253797 bsc#1253799). - CVE-2025-58190: golang.org/x/net/html: specially crafted input can cause excessive memory consumption by `html.ParseFragment` (bsc#1251559). - CVE-2026-25680,CVE-2026-25681,CVE-2026-27136,CVE-2026-42502,CVE-2026-42506: golang.org/x/net/html: multiple issues when parsing HTML files (bsc#1267058). - CVE-2026-25934: github.com/go-git/go-git/v5: improper verification of data integrity values for `.pack` and `.idx` files can lead to the consumption of corrupted files (bsc#1258096). - CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 `:path` pseudo-header (bsc#1260139 bsc#1260149 bsc#1260180). - CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266477 bsc#1266482 bsc#1266541 bsc#1266547). - CVE-2026-39827,CVE-2026-39828,CVE-2026-39829,CVE-2026-39830,CVE-2026-39831,CVE-2026-39832,CVE-2026-39833, CVE-2026-39834,CVE-2026-39835,CVE-2026-42508,CVE-2026-46595,CVE-2026-46597,CVE-2026-46598: golang.org/x/crypto/ssh: multiple issues in the crypto/ssh library (bsc#1266051 bsc#1266057 bsc#1266086 bsc#1266112 bsc#1266122 bsc#1266127 bsc#1266132 bsc#1266150 bsc#1266160). - CVE-2026-41506: github.com/go-git/go-git/v5: HTTP authentication credential leak when following redirects during smart-HTTP clone and fetch operations (bsc#1264862 bsc#1264888 bsc#1264938). - CVE-2026-41602: github.com/apache/thrift: `TFramedTransport` frame size headers can lead to a `uint32` integer overflow (bsc#1263515). - CVE-2026-41603: github.com/apache/thrift: improper hostname verification in `TSSLTransportFactory` can lead to host mismatch (bsc#1263606). - CVE-2026-41604: github.com/apache/thrift: swift input with an invalid field range can lead to an out-of-bounds read and application crash (bsc#1263445). - CVE-2026-41605: github.com/apache/thrift: compact protocol messages with large integer values can lead to integer overflow (bsc#1263411). - CVE-2026-41606: github.com/apache/thrift: crafted nested messages in `c_glib` dispatch can lead to uncontrolled recursion and denial of service (bsc#1263357). - CVE-2026-41607: github.com/apache/thrift: crafted message with improper length validation can lead to an out-of-bounds read and potential information disclosure (bsc#1263313). - CVE-2026-41636: github.com/apache/thrift: uncontrolled recursion in Node.js bindings can lead to denial of service via stack exhaustion (bsc#1263247). - CVE-2026-44740: github.com/go-git/go-billy/v5: improper input handling in many components can lead to DoS via infinite loops, panics or resource consumption (bsc#1267271 bsc#1267273 bsc#1267276).

Exploit probability Not scored
Published July 15, 2026
Required by Not available
Last source change July 16, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Module for Public Cloud 15 SP4 terraform-provider-aws
SUSE:Linux Enterprise Module for Public Cloud 15 SP4 terraform-provider-azurerm
SUSE:Linux Enterprise Module for Public Cloud 15 SP4 terraform-provider-external
SUSE:Linux Enterprise Module for Public Cloud 15 SP4 terraform-provider-google
SUSE:Linux Enterprise Module for Public Cloud 15 SP4 terraform-provider-helm
SUSE:Linux Enterprise Module for Public Cloud 15 SP4 terraform-provider-kubernetes
SUSE:Linux Enterprise Module for Public Cloud 15 SP4 terraform-provider-local
SUSE:Linux Enterprise Module for Public Cloud 15 SP4 terraform-provider-null
SUSE:Linux Enterprise Module for Public Cloud 15 SP4 terraform-provider-random
SUSE:Linux Enterprise Module for Public Cloud 15 SP4 terraform-provider-tls
SUSE:Linux Enterprise Module for Public Cloud 15 SP5 terraform-provider-aws
SUSE:Linux Enterprise Module for Public Cloud 15 SP5 terraform-provider-azurerm
SUSE:Linux Enterprise Module for Public Cloud 15 SP5 terraform-provider-external
SUSE:Linux Enterprise Module for Public Cloud 15 SP5 terraform-provider-google
SUSE:Linux Enterprise Module for Public Cloud 15 SP5 terraform-provider-helm
SUSE:Linux Enterprise Module for Public Cloud 15 SP5 terraform-provider-kubernetes
SUSE:Linux Enterprise Module for Public Cloud 15 SP5 terraform-provider-local
SUSE:Linux Enterprise Module for Public Cloud 15 SP5 terraform-provider-null
SUSE:Linux Enterprise Module for Public Cloud 15 SP5 terraform-provider-random
SUSE:Linux Enterprise Module for Public Cloud 15 SP5 terraform-provider-tls

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:3056-1

This update for terraform-provider-aws, terraform-provider-azurerm, terraform-provider-external, terraform-provider-google, terraform-provider-helm, terraform-provider-kubernetes, terraform-provider-local, terraform-provider-null, terraform-provider-random, terraform-provider-tls fixes the following issues - CVE-2022-41723: go1.19,go1.20: net/http2: quadratic complexity in HPACK decoding (bsc#1208300). - CVE-2025-22872: golang.org/x/net/html: incorrectly interpreted tags can cause content to be placed wrong scope during DOM construction (bsc#1241728). - CVE-2025-32386: helm: specially crafted chart archive can cause OOM termination (bsc#1241030). - CVE-2025-32387: helm: specially crafted JSON schema can cause a stack overflow (bsc#1241033). - CVE-2025-47911: golang.org/x/net/html: various algorithms have quadratic complexity when parsing HTML documents (bsc#1251365). - CVE-2025-47913: golang.org/x/crypto/ssh/agent: client process termination when receiving an unexpected message type in response to a key listing or signing request (bsc#1253508 bsc#1253517). - CVE-2025-47914: golang.org/x/crypto/ssh/agent: non validated message size can cause a panic due to an out of bounds read (bsc#1253980 bsc#1253983). - CVE-2025-58181: golang.org/x/crypto/ssh: invalidated number of mechanisms can cause unbounded memory consumption (bsc#1253797 bsc#1253799). - CVE-2025-58190: golang.org/x/net/html: specially crafted input can cause excessive memory consumption by `html.ParseFragment` (bsc#1251559). - CVE-2026-25680,CVE-2026-25681,CVE-2026-27136,CVE-2026-42502,CVE-2026-42506: golang.org/x/net/html: multiple issues when parsing HTML files (bsc#1267058). - CVE-2026-25934: github.com/go-git/go-git/v5: improper verification of data integrity values for `.pack` and `.idx` files can lead to the consumption of corrupted files (bsc#1258096). - CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 `:path` pseudo-header (bsc#1260139 bsc#1260149 bsc#1260180). - CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266477 bsc#1266482 bsc#1266541 bsc#1266547). - CVE-2026-39827,CVE-2026-39828,CVE-2026-39829,CVE-2026-39830,CVE-2026-39831,CVE-2026-39832,CVE-2026-39833, CVE-2026-39834,CVE-2026-39835,CVE-2026-42508,CVE-2026-46595,CVE-2026-46597,CVE-2026-46598: golang.org/x/crypto/ssh: multiple issues in the crypto/ssh library (bsc#1266051 bsc#1266057 bsc#1266086 bsc#1266112 bsc#1266122 bsc#1266127 bsc#1266132 bsc#1266150 bsc#1266160). - CVE-2026-41506: github.com/go-git/go-git/v5: HTTP authentication credential leak when following redirects during smart-HTTP clone and fetch operations (bsc#1264862 bsc#1264888 bsc#1264938). - CVE-2026-41602: github.com/apache/thrift: `TFramedTransport` frame size headers can lead to a `uint32` integer overflow (bsc#1263515). - CVE-2026-41603: github.com/apache/thrift: improper hostname verification in `TSSLTransportFactory` can lead to host mismatch (bsc#1263606). - CVE-2026-41604: github.com/apache/thrift: swift input with an invalid field range can lead to an out-of-bounds read and application crash (bsc#1263445). - CVE-2026-41605: github.com/apache/thrift: compact protocol messages with large integer values can lead to integer overflow (bsc#1263411). - CVE-2026-41606: github.com/apache/thrift: crafted nested messages in `c_glib` dispatch can lead to uncontrolled recursion and denial of service (bsc#1263357). - CVE-2026-41607: github.com/apache/thrift: crafted message with improper length validation can lead to an out-of-bounds read and potential information disclosure (bsc#1263313). - CVE-2026-41636: github.com/apache/thrift: uncontrolled recursion in Node.js bindings can lead to denial of service via stack exhaustion (bsc#1263247). - CVE-2026-44740: github.com/go-git/go-billy/v5: improper input handling in many components can lead to DoS via infinite loops, panics or resource consumption (bsc#1267271 bsc#1267273 bsc#1267276).

View original source

05 / REFERENCES

Further evidence